Tag
high
advisory
Steeltoe Environment Actuator Vulnerability (CVE-2026-50200) Leaks Database Passwords
1 rule 1 TTP 1 CVEA high-severity vulnerability, CVE-2026-50200, in the Steeltoe `Sanitizer` component of the Environment actuator allows for the unintended disclosure of sensitive connection string values, including embedded plaintext credentials, when the `/actuator/env` endpoint is accessed, enabling direct database connection and bypassing application-tier security.
Steeltoe.Management.Endpoint <= 4.1.0 +1
credential-access
vulnerability
.net
steeltoe
webserver
actuator
1r
1t
1c
high
advisory
Spring Boot Actuator Misconfiguration Leads to Potential SharePoint Exfiltration via Stolen Credentials
2 rules 4 TTPs 1 IOCA threat actor can exploit a misconfigured Spring Boot Actuator to steal credentials and potentially exfiltrate data from SharePoint after bypassing MFA.
Spring Boot +1
spring-boot
actuator
sharepoint
credential-theft
data-exfiltration
2r
4t
1i